CVE-2025-36128
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-16
Last updated on: 2025-10-28
Assigner: IBM Corporation
Description
Description
IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | mq | 9.1.0.0 |
| ibm | mq | 9.2.0.0 |
| ibm | mq | 9.3.0 |
| ibm | mq | 9.3.0.0 |
| ibm | mq | 9.4.0 |
| ibm | mq | 9.4.0.0 |
| ibm | aix | * |
| ibm | i | * |
| microsoft | windows | * |
| oracle | solaris | * |
| linux | linux_kernel | From 5.15.160 (inc) to 5.16 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-772 | The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed. |